Control who can do what

Give people only the actions they need

Give operators the actions they need while keeping unrelated administration out of reach.

Captured from the product Demo workspace
Let someone run or approve an agent without also letting them edit it or administer the workspace.

What this changes for your team.

Permissions are split by action so reading a run, executing an agent, approving a write, and managing credentials do not collapse into one broad role check. Effective access still comes from the assigned organization and domain roles.

How it works in practice.

  1. 01

    Map each role to explicit permission grants at its organization or domain boundary.

  2. 02

    Check the relevant grant for the requested resource and action on the server.

  3. 03

    Return a uniform denial without relying on whether the frontend exposed the control.

What you can plan around.

The behaviour you can design against, stated concretely.

View, execute, approve, authoring, knowledge, trigger, webhook, connection, and member actions have distinct permission checks.

Resource queries include organization or domain scope in addition to the action grant.

Tests exercise cross-organization and insufficient-role access paths.

Bring one real process

See how Yekar.AI fits the way you work.

Start with a job your team already owns, plus the tools and decisions around it.

Talk to us